← Back to browse · API

CVE-2023-0232

Severity
CRITICAL
CVSS
9.8
EPSS
0.03317
Risk score
40.36
CISA KEV
No
PoC
No
Published
2023-02-21
Modified
2025-03-12
First seen
2026-08-07
Aliases
EUVD-2023-12316, GHSA-HP6X-RRX2-386M
Products
HasTech:ShopLentor 0 <2.5.4
Sources
euvd EUVD-2023-12316

Description

The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.

References